|
News,
Internal,
Projects,
Home Software, Support, Documentation |
Limiting... Àº ÀÌ ¼¹ö¿¡¼ ´Ù¸¥ ¼¹ö¿¡ Ping ÇÒ ¶§°¡ ¾Æ´Ï¶ó ´Ù¸¥
¼¹ö¿¡¼ ÀÌ ¼¹ö¿¡ pingÀ» ³Ê¹« ¸¹ÀÌ ÇÒ ¶§ ½º½º·Î ÀÀ´ä·üÀ» Á¦ÇÑÇÏ´Â
°ÍÀÔ´Ï´Ù.. Áï °ø°Ý¹Þ°í ÀÖ´Ù°í º¸½Ã´Â °ÍÀÌ ÁÁ°Ú°í¿ä...
ipfw ¸¦ »ç¿ëÇÒ ¼ö ÀÖÀ¸¸é icmp ÆÐŶÀ» ¸ðµÎ ¸·¾Æ º¸¼¼¿ä.
ipfw add <¹øÈ£> deny icmp from any to any
·ê¼Â ¹øÈ£´Â ±âÁ¸ ±ÔÄ¢ÀÌ ÀÖÀ» °æ¿ì Àû´çÇÑ °÷¿¡ ³¢¿ö³Ö¾î¾ß ÇÕ´Ï´Ù. ipfw
±ÔÄ¢ÀÌ ¾Æ¹«°Íµµ ¾ø´Ù¸é 1000 Á¤µµ ÁÖ½Ã¸é µË´Ï´Ù.
apache¿¡ ½×ÀÌ´Â ·Î±× ¹®Á¦´Â Nimda/Code Red °ø°ÝÀ¸·Î ¸»¾¸µå·È´Âµ¥ ÀÌ
½Ã½ºÅÛÀ̳ª ´Ù¸¥ ½Ã½ºÅÛ¿¡ ÇØ¸¦ ³¢Ä¡Áö ¾Ê½À´Ï´Ù. Windows ½Ã½ºÅÛ¸¸ °ø°ÝÀ»
¹ÞÀ» °¡´É¼ºÀÌ Àֱ⠶§¹®ÀÔ´Ï´Ù.
httpd¸¦ ³»·Á³õ°í, tcpdump µîÀ» »ç¿ëÇØ¼ ¹«½¼ ÆÐŶÀÌ ¶Ç ¿À°í°¡´ÂÁö
»ìÆìº¸¼¼¿ä.. ±×¸®°í netstat À» »ç¿ëÇØ¼ ¸ð¸£´Â °÷¿¡¼ ¿¬°áµÈ °ÍÀÌ
ÀÖ´ÂÁö »ìÆìº¸½Ã±â ¹Ù¶ø´Ï´Ù.
From: Pyun YongHyeon <yongari@kt-is.co.kr>
Subject: Re: ¼Ó¼ÓÆí - ÇØÅ·½Ãµµ-Àç¹ß
Date: Sat, 5 Oct 2002 12:44:13 +0900
> On Fri, Oct 04, 2002 at 03:56:50PM -0700, sammycom wrote:
> >> ¼Ó¼ÓÆí - ÇØÅ·½Ãµµ-Àç¹ß
> >>
> >> ¹®Á¦µÇ´ø FreeBSD¼¹ö(66.218.xxx.133)¸¦ ´Ù½Ã ?V¾÷ÇÏ°í³ª¼ ÀÏÁÖÀϰ£Àº ¸ðµç°Ô Á¤»óÀûÀÎ°Í °°´õ´Ï
> >> ¶È°°Àº ¹®Á¦°¡ ´Ù½Ã °Ô¼ÓÀϾ´Ï´Ù.
> >> ¾ÆÆÄÄ¡+ssl ¹®Á¦ÀÎ°Í °°¾Æ¼ httpd¸¦ ¾Æ¿¹ Á׿©¹ö¸®°í, named ±îÁö Áö¿öµµ ¸¶Âù°¡Áö¿¡¿ä ÀÌ ¼¹ö¸¸ ³×Æ®¿ö¿¡ ¹°¸®¸é
> >> ´Ù¸¥ ³ª¸ÓÁöÀÇ ¾ÆÀÌÇÇ ÄÄ(66.218.xx.132) ¿¡¼µµ default gateway(66.218.xx.1) ±îÁöµµ ÀÎÅͳÝÀÌ ³ª±âÁú ¸øÇÔ´Ï´Ù.
> >> ±×¸®°í ·Î±×ÆÄÀÏ(/var/log/messages)¿¡ ´ÙÀ½°ú °°Àº ·Î±×°¡ 1Ãʰ£°ÝÀ¸·Î ½×ÀÔ´Ï´Ù.
> >> ·Î±×ÆÄÀÏ¿¡¸¸ ½×ÀÌ´Â°Ô ¾Æ´Ï°í Äָܼð´ÏÅÍ¿¡ °Ô¼Ó ³ª¿É´Ï´Ù.
> >>
> >> Limiging icmp unreach from 204 to 200 packet per second
> >> Limiging icmp unreach from 271to 200 packet per second
> >> Limiging icmp unreach from 231to 200 packet per second
> >> Limiging icmp unreach from 220to 200 packet per second
> >> ...(¾ÆÀÌÇÇ ¹øÈ£°°Àº°Å´Â ¾ø±¸¿ä)
> >>
> ½Ã½ºÅÛÀÇ ÇØÅ·ÀÌ Àǽɽº·´½À´Ï´Ù.
> 1. ICMP port unreachable code´Â UDP·Î Á¢¼Ó½Ãµµ½Ã ÇØ´ç ¼¹ö¿¡ ¼ºñ½º°¡
> ¾øÀ» °æ¿ì Á¢¼ÓÇÑ ¼¹ö¿¡¼ »ý¼ºÇÕ´Ï´Ù.
> ÇØÅ·µÈ ÈÄ rootkit°°Àº °ÍÀÌ ¼³Ä¡µÇ¾î¼ ´Ù¸¥ ¿©·¯ ½Ã½ºÅÛÀ» °Ë»çÇϰí ÀÖÀ» °æ¿ì
> ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù.
>
> 2. ÀÌ ½Ã½ºÅÛ¸¸ ¿¬°áÇÏ¸é ´Ù¸¥ ½Ã½ºÅÛµµ networkÀÌ µÇÁö ¾Ê´Â´Ù°í Çϴ°ÍÀ» º¸¸é
> ¾Æ¸¶µµ ÀÌ ½Ã½ºÅÛ¿¡¼ network¿¡ »ó´çÇÑ ºÎÇϸ¦ ÁÖ´Â ÀÏÀ» Çϰí ÀÖÀ» ¼ö ÀÖ½À´Ï´Ù.
>
> °°Àº ¹öÁ¯ÀÇ ±ú²ýÇѽýºÅÛ°ú hash °ªÀ» ºñ±³ÇØ º¸½Ã±â ¹Ù¶ø´Ï´Ù.
> cksum(1), sum(1)Àº È¿°ú°¡ ¾ø°í ¹Ýµå½Ã Cryptographic HashingÀ» »ç¿ëÇØ¾ß ÇÕ´Ï´Ù.
> ´ëÇ¥ÀûÀÎ °ÍÀ¸·Î´Â MD5, RIPEMD160 µîÀÌ ÀÖ½À´Ï´Ù.
> MD5°ªÀº md5(1)³ª openssl(1)·Î ±¸ÇÒ ¼ö ÀÖ½À´Ï´Ù.
> ÃÖ¼ÒÇÑ ´ÙÀ½ÀÇ ÇÁ·Î±×·¥¿¡ ´ëÇØ¼ ¸ðµÎ °Ë»çÇϰí Çϳª¶óµµ ´Ù¸¥°ÍÀÌ ÀÖ´Ù¸é
> µ¥ÀÌŸ ¹é¾÷ÈÄ ½Ã½ºÅÛÀ» »õ·Î ¼³Ä¡Çϼ¼¿ä.
>
> ls, ps, ifconfig, md5, openssl, top, netstat,
> sockstat, fstat, sshd, inetd, telnetd, syslogd µî
>
> >>
> >> ¾î´ÀºÐ Á¶¾ð´ë·Î °°Àº ¼ºê³Ý(66.218.32.0/19 : 66.218.32.0 - 66.218.63.255)
> >> À» »ç¿ëÇÏ´Â ±× ÁÖº¯µ¿³×(¶Ç´Â) ÀÇ ¹ÙÀÌ·¯½º°¨¿°µÈ Äͧ¹®¿¡ ±×·²¼öµµ ÀÖ´Â°Í °°¾Æ¼ ISP ¿¡ ¹®ÀÇ, Ç×ÀÇ ÇßÁö¸¸.
> >>
> >> ISP ¿Ð : ÁøÂ¥·Î ¾î´À ¾ÆÀÌÇÇÀÇ ¹ÙÀÌ·¯½º¶§¹®ÀÎÁö È®ÀÎÇÒ¼öµµ ¾ø´Â »óȲ¿¡¼ ·Î±×ÆÄÀϸ¸ °®°í¼
> >> ip¼ÒÀ¯ÇÑ »ç¿ëÀÚ ÀÏÀÏÀÌ ³Ê³× ÄĹÙÀÌ·¯½º¶§¹®¿¡ °°Àº Áö¿ª ´Ù¸¥»ç¿ëÀÚ°¡ ÇÇÇØº»´Ù°í ÇÒ¼öµµ ¾ø°í ¶Ç °¡°¢ »ç¿ëÀÚÀÇ ¹ÙÀÌ·¯½º ¹®Á¦±îÁö °£¼·Çϰųª È®ÀÎÇÒ¼öÀÖ´Â ¹®Á¦°¡ ¾Æ´Ï¶ó°í ¸¸ ÇÏ´Ï , ±× ¶ÇÇÑ Àϸ®ÀÖ´Â ¸»À̱⵵ ÇÕ´Ï´Ù.
> >>
> ¸Â½À´Ï´Ù. ISP°¡ ÃëÇÒ ¼ö ÀÖ´Â Á¶Ä¡¶ó´Â°ÍÀº °ÅÀÇ ¾ø½À´Ï´Ù.
> ±â²¯ÇØ¾ß ISP°¡ °ü¸®ÇÏ´Â ¼¹öÁß ¹®Á¦ÀÖ´Â ¼¹öÀÇ ºÐ¸®Á¤µµ ÀÔ´Ï´Ù.
> ÀÌ ¸¶Àúµµ ¸¹ÀÌ ÁÖÀúÇÏ´Â ÆíÀÌÁÒ.
>
> >> ±×¸®°í httpd ·Î±×ÆÄÀϺ¸´Ï±î 66.218.xxx.yyy: ....scipt/winnt/cmd.exe ¾î¼±¸ ÇÏ´Â ÁÙÀÌ ²À °°Àº ¼ºê³Ý¿¡¼
> >> µé¾î¿À´Â°Íµµ ÀÖÁö¸¸
> >> 24.xxx.xxx.xxx: : ....scipt/winnt/cmd.exe
> >> 206.xxx.xxx.xx. : ....scipt/winnt/cmd.exe
> >> ..
> >> ÀÌ·¸°Ô ÀüÇô ´Ù¸¥ ³×Æ®¿öÅ© ÁÖ¼Ò¿¡¼µµ µé¾î¿À´õ¶ó±¸¿ä.
> >>
> >> ÀÌ·²¶§´Â ¾î¶»°Ô ÇØ¾ßÇÒÁö ¸ð¸£°Ú³×¿ä
> ÀÌ°Ç ¾î´À¼¹ö¿¡³ª ÀÖ´Â Á¤»óÀûÀÎ Çö»óÀÔ´Ï´Ù.
> ÀÎÅͳݻ󿡼´Â ¹ÙÀÌ·¯½º³ª ¿ú¿¡ °¨¿°µÈ ¼¹öµéÀÌ °ø°Ý´ë»óÀ» Ç×»ó ã°í Àְŵç¿ä.
> ±×¸®°í ÇØÅ°À» °øºÎ(?)ÇÏ´Â Ãʺ¸ÀÚµéÀÌ °ø°ÝÇÁ·Î±×·¥À» ±¸Çؼ ½ÃÇèÇϱ⵵ ÇÕ´Ï´Ù.
>
> --
> ============================================================
> // Korea Telecom Internet Solutions, Inc.
> // FreeBSD/Linux Professional Consulting/Tech. Support
> //
> // Pyun YongHyeon
> //
> // WWW: http://www.kt-is.co.kr/
> // FTP: ftp://ftp.kt-is.co.kr/
> //
> // TEL: +82-2-364-0400
> // FAX: +82-2-364-9119
> ============================================================
> --
> Please look and take part in KFUG FAQ: <http://www.kr.freebsd.org/FAQ-kr/>
> To Unsubscribe: send mail to majordomo@kr.FreeBSD.org
> with "unsubscribe questions" in the BODY of the message
--
CHOI Junho <http://www.kr.FreeBSD.org/~cjh>
$mail->{"Korea FreeBSD Users Group"} = "cjh at kr.FreeBSD.org";
$mail->{"FreeBSD Committer"} = "cjh at FreeBSD.org";
$mail->{"Web Data Bank"} = "cjh at wdb.co.kr";
--
Please look and take part in KFUG FAQ: <http://www.kr.freebsd.org/FAQ-kr/>
To Unsubscribe: send mail to majordomo@kr.FreeBSD.org
with "unsubscribe questions" in the BODY of the message
|
Copyright © 1998-2005 Korea FreeBSD Users Group. All rights reserved. webmaster at kr.FreeBSD.org $Date: 2002/10/31 23:00:24 $ |
|